Back to skill

Security audit

Logo设计工具专业版

Security checks for vulnerabilities and agentic risk

Overview

This logo-design skill is not clearly malicious, but it asks for command execution, file writing, external AI/API use, and credential handling without enough scoping or disclosure.

Review this skill before installing. Use it only in a dedicated project workspace, avoid running generated commands blindly, pin and isolate any Python dependencies, do not run it as administrator, and provide API keys only for a known image provider after confirming what brand data will be transmitted.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:239
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 239-240
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
| Vectorization tool | Library | Recommended | pip install potrace |
| Image processing library | Library | Recommended | pip install Pillow |

Technical Analysis

The Skill instructs users to install third-party Python packages without specifying reviewed versions, package hashes, a lockfile, or a trusted package index. Consequently, package resolution depends on mutable package-index state and the user's local pip configuration.

Python package installation can execute package-controlled build logic. If a dependency release, transitive dependency, package-index account, or configured package source is compromised, following these commands could execute attacker-controlled code during installation. The lack of version and integrity constraints also makes builds non-reproducible and prevents verification that users install the same artifacts that were security-reviewed.

The packages are presented as recommended rather than automatically installed, which reduces exploitability but does not eliminate the supply-chain risk for users who follow the documented setup instructions.

Attack Path

  1. An attacker compromises a referenced package release, one of its transitive dependencies, or a package source configured in the user's pip environment.
  2. The user follows the documented pip install potrace or pip install Pillow instruction.
  3. pip resolves the current package version and dependencies without checking against project-provided hashes or a reviewed lockfile.
  4. A malicious source distribution or build dependency executes attacker-controlled installation logic.
  5. The payload runs with the privileges of the account invoking pip and may access files, credentials, environment variables, and network resources available to that account.
  6. Impact c ...[truncated 890 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin each direct dependency to a reviewed version rather than installing the latest available release:
    text
    Pillow==<reviewed-version>
    potrace==<reviewed-version>
    
  2. Generate and distribute a lockfile containing resolved transitive dependencies.
  3. Record cryptographic hashes for every permitted artifact and install with pip's --require-hashes option.
  4. Explicitly use a trusted package index, while ensuring that mirrors and pip configuration cannot silently redirect resolution to an untrusted source.
  5. Prefer reviewed binary wheels where appropriate and disable unnecessary source builds.
  6. Install dependencies in an isolated virtual environment under an unprivileged account.
  7. Remove the recommendation to run with administrator privileges at SKILL.md:415; instead, troubleshoot ownership and virtual-environment permissions using least privilege.
  8. Add automated dependency scanning and periodically review pinned versions for known vulnerabilities.
  9. Document a controlled update process requiring integrity verification and security review before dependency versions are changed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation language is broad enough to match many ordinary creative requests, which increases the likelihood that the skill is auto-selected in contexts where users did not intend file writes, external API use, or command execution. Because this skill advertises exec/write capabilities, overbroad triggering materially raises the risk of unnecessary privileged actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description states '支持中文交互,无需复杂配置即开即用,' while the skill metadata and instructions do not offer language selection or explain that the skill is intentionally region-specific. This can be a language/locale policy issue because it signals a default language constraint without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents command execution and writing outputs to local directories, but does not prominently warn that running it may modify the filesystem. In an agent environment with read/exec/write tools, missing disclosure can lead to surprising local changes, overwrites, or execution of unsafe commands assembled from user-provided parameters.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill references external AI services, API key configuration, and load-balanced key usage without clearly warning that user content may be transmitted to third parties. This creates a privacy and compliance risk, especially if brand assets, prompts, or proprietary materials are sent off-platform without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document first says no extra API key is needed, then states that image-generation tools require API keys and that key pools/multi-account rotation are supported. Contradictory security-relevant guidance can mislead users about secret handling and trust boundaries, resulting in accidental credential exposure or enabling hidden external calls.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is presented as a logo/design tool, but later instructions expand into generic API credential setup, API calling, and operational guidance that is not tightly scoped to logo generation. That mismatch can cause an agent or user to authorize broader external-service use than expected, increasing the chance of unintended data disclosure or overbroad execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.